perf/x86/core: Completely disable guest PEBS via guest's global_ctrl
authorLike Xu <likexu@tencent.com>
Wed, 31 Aug 2022 03:35:24 +0000 (11:35 +0800)
committerPaolo Bonzini <pbonzini@redhat.com>
Thu, 1 Sep 2022 23:20:59 +0000 (19:20 -0400)
When a guest PEBS counter is cross-mapped by a host counter, software
will remove the corresponding bit in the arr[global_ctrl].guest and
expect hardware to perform a change of state "from enable to disable"
via the msr_slot[] switch during the vmx transaction.

The real world is that if user adjust the counter overflow value small
enough, it still opens a tiny race window for the previously PEBS-enabled
counter to write cross-mapped PEBS records into the guest's PEBS buffer,
when arr[global_ctrl].guest has been prioritised (switch_msr_special stuff)
to switch into the enabled state, while the arr[pebs_enable].guest has not.

Close this window by clearing invalid bits in the arr[global_ctrl].guest.

Cc: linux-perf-users@vger.kernel.org
Cc: Kan Liang <kan.liang@linux.intel.com>
Cc: Peter Zijlstra <peterz@infradead.org>
Cc: Sean Christopherson <seanjc@google.com>
Fixes: 854250329c02 ("KVM: x86/pmu: Disable guest PEBS temporarily in two rare situations")
Signed-off-by: Like Xu <likexu@tencent.com>
Message-Id: <20220831033524.58561-1-likexu@tencent.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
arch/x86/events/intel/core.c

index 2db9349..75cdd11 100644 (file)
@@ -4052,8 +4052,9 @@ static struct perf_guest_switch_msr *intel_guest_get_msrs(int *nr, void *data)
                /* Disable guest PEBS if host PEBS is enabled. */
                arr[pebs_enable].guest = 0;
        } else {
-               /* Disable guest PEBS for cross-mapped PEBS counters. */
+               /* Disable guest PEBS thoroughly for cross-mapped PEBS counters. */
                arr[pebs_enable].guest &= ~kvm_pmu->host_cross_mapped_mask;
+               arr[global_ctrl].guest &= ~kvm_pmu->host_cross_mapped_mask;
                /* Set hw GLOBAL_CTRL bits for PEBS counter when it runs for guest */
                arr[global_ctrl].guest |= arr[pebs_enable].guest;
        }